Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 366 653

Количество 366 653

github логотип

GHSA-434x-w66g-qw3r

7 месяцев назад

bytes has integer overflow in BytesMut::reserve

EPSS: Низкий
github логотип

GHSA-434x-fc83-9vc7

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in CM68 News allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-434x-f5f5-g62j

больше 4 лет назад

An elevation of privilege vulnerability exists when the Windows Work Folders Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Work Folders Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1484, CVE-2020-1516.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-434x-65h3-cg6q

больше 3 лет назад

A DLL Hijacking issue discovered in Soft-o Free Password Manager 1.1.20 allows attackers to create arbitrary DLLs leading to code execution.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-434w-vx58-3f68

больше 4 лет назад

IBM AIX contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-434w-5hh5-c4p5

10 месяцев назад

An issue was discovered in VTS in Samsung Mobile Processor and Wearable Processor Exynos 1080, 1280, 2200, 1380, 1480, 2400, 1580, 2500, W920, W930, W1000. A race condition in the VTS driver results in an out-of-bounds read, leading to an information leak.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-434w-2p2w-phjf

3 месяца назад

A security vulnerability has been detected in Edimax EW-7438RPn 1.31. The affected element is the function formLogout of the file /goform/formLogout. The manipulation of the argument submit-url leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-434v-x5qv-pmh6

5 месяцев назад

libcrux has All-Zero Key Generation Upon Catastrophic RNG Failure

EPSS: Низкий
github логотип

GHSA-434v-9hrw-chfc

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in BracketSpace Simple Post Notes.This issue affects Simple Post Notes: from n/a through 1.7.6.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-434r-hj47-rpjj

6 месяцев назад

The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Unvalidated Redirect in all versions up to, and including, 3.2.24. This is due to insufficient validation on the redirect url supplied via the 'rcp_redirect' parameter. This makes it possible for unauthenticated attackers to redirect users with the password reset email to potentially malicious sites if they can successfully trick them into performing an action.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-434r-f9m8-6m25

больше 4 лет назад

Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.0.4 has unknown impact and remote authenticated attack vectors, a different vulnerability than CVE-2008-2586.

EPSS: Низкий
github логотип

GHSA-434r-7c99-hwf3

3 месяца назад

Nanobot contains a server-side request forgery vulnerability in the web_fetch tool

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-434r-58rq-9884

около 1 месяца назад

Use after free in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-434r-4m9g-54qc

больше 4 лет назад

The server in Cisco Unity Connection 9.1(1) and 9.1(2) allows remote authenticated users to obtain privileged access by conducting an "HTTP Intercept" attack and leveraging the ability to read files within the context of the web-server user account, aka Bug ID CSCup41014.

EPSS: Низкий
github логотип

GHSA-434q-xw85-56v7

больше 1 года назад

Stored Cross-Site Scripting (XSS) vulnerability in Prestashop 8.1.7, due to the lack of proper validation of user input through ‘/<admin_directory>/index.php’, affecting the ‘link’ parameter. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal their cookie session details.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-434q-p653-pccw

больше 4 лет назад

mod_access_referer 1.0.2 allows remote attackers to cause a denial of service (crash) via a malformed Referer header that is missing a hostname, as parsed by the ap_parse_uri_components function in Apache, which triggers a null dereference.

EPSS: Низкий
github логотип

GHSA-434p-vvgh-4rf9

4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: usb: misc: usbio: Fix URB memory leak on submit failure When usb_submit_urb() fails in usbio_probe(), the previously allocated URB is never freed, causing a memory leak. Fix this by jumping to err_free_urb label to properly release the URB on the error path.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-434m-x855-gvj6

больше 4 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality via unknown vectors related to Serviceability. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to insufficient indication of an SSL connection failure by JConsole, related to RMI connection dialog box.

EPSS: Низкий
github логотип

GHSA-434m-p5cc-25vp

около 2 месяцев назад

Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext transmission of sensitive information vulnerability.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-434j-v2p8-3fcp

больше 4 лет назад

NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where an improper input parameter handling may lead to a denial of service or potential escalation of privileges.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-434x-w66g-qw3r

bytes has integer overflow in BytesMut::reserve

1%
Низкий
7 месяцев назад
github логотип
GHSA-434x-fc83-9vc7

Cross-site scripting (XSS) vulnerability in CM68 News allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-434x-f5f5-g62j

An elevation of privilege vulnerability exists when the Windows Work Folders Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Work Folders Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1484, CVE-2020-1516.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-434x-65h3-cg6q

A DLL Hijacking issue discovered in Soft-o Free Password Manager 1.1.20 allows attackers to create arbitrary DLLs leading to code execution.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-434w-vx58-3f68

IBM AIX contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges.

CVSS3: 7.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-434w-5hh5-c4p5

An issue was discovered in VTS in Samsung Mobile Processor and Wearable Processor Exynos 1080, 1280, 2200, 1380, 1480, 2400, 1580, 2500, W920, W930, W1000. A race condition in the VTS driver results in an out-of-bounds read, leading to an information leak.

CVSS3: 5.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-434w-2p2w-phjf

A security vulnerability has been detected in Edimax EW-7438RPn 1.31. The affected element is the function formLogout of the file /goform/formLogout. The manipulation of the argument submit-url leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
1%
Низкий
3 месяца назад
github логотип
GHSA-434v-x5qv-pmh6

libcrux has All-Zero Key Generation Upon Catastrophic RNG Failure

5 месяцев назад
github логотип
GHSA-434v-9hrw-chfc

Cross-Site Request Forgery (CSRF) vulnerability in BracketSpace Simple Post Notes.This issue affects Simple Post Notes: from n/a through 1.7.6.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-434r-hj47-rpjj

The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Unvalidated Redirect in all versions up to, and including, 3.2.24. This is due to insufficient validation on the redirect url supplied via the 'rcp_redirect' parameter. This makes it possible for unauthenticated attackers to redirect users with the password reset email to potentially malicious sites if they can successfully trick them into performing an action.

CVSS3: 4.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-434r-f9m8-6m25

Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.0.4 has unknown impact and remote authenticated attack vectors, a different vulnerability than CVE-2008-2586.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-434r-7c99-hwf3

Nanobot contains a server-side request forgery vulnerability in the web_fetch tool

CVSS3: 5
0%
Низкий
3 месяца назад
github логотип
GHSA-434r-58rq-9884

Use after free in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 8.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-434r-4m9g-54qc

The server in Cisco Unity Connection 9.1(1) and 9.1(2) allows remote authenticated users to obtain privileged access by conducting an "HTTP Intercept" attack and leveraging the ability to read files within the context of the web-server user account, aka Bug ID CSCup41014.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-434q-xw85-56v7

Stored Cross-Site Scripting (XSS) vulnerability in Prestashop 8.1.7, due to the lack of proper validation of user input through ‘/<admin_directory>/index.php’, affecting the ‘link’ parameter. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal their cookie session details.

CVSS3: 4.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-434q-p653-pccw

mod_access_referer 1.0.2 allows remote attackers to cause a denial of service (crash) via a malformed Referer header that is missing a hostname, as parsed by the ap_parse_uri_components function in Apache, which triggers a null dereference.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-434p-vvgh-4rf9

In the Linux kernel, the following vulnerability has been resolved: usb: misc: usbio: Fix URB memory leak on submit failure When usb_submit_urb() fails in usbio_probe(), the previously allocated URB is never freed, causing a memory leak. Fix this by jumping to err_free_urb label to properly release the URB on the error path.

CVSS3: 5.5
0%
Низкий
4 месяца назад
github логотип
GHSA-434m-x855-gvj6

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality via unknown vectors related to Serviceability. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to insufficient indication of an SSL connection failure by JConsole, related to RMI connection dialog box.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-434m-p5cc-25vp

Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext transmission of sensitive information vulnerability.

CVSS3: 4.3
1%
Низкий
около 2 месяцев назад
github логотип
GHSA-434j-v2p8-3fcp

NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where an improper input parameter handling may lead to a denial of service or potential escalation of privileges.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу